CVE-2024-9393
- EPSS 0.16%
- Veröffentlicht 01.10.2024 16:15:10
- Zuletzt bearbeitet 03.11.2025 23:17:33
An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://pdf.js` origin. This could allow them to access cross-origin PDF content. This access is limited to "same site" documents by the Site I...
CVE-2024-9394
- EPSS 0.11%
- Veröffentlicht 01.10.2024 16:15:10
- Zuletzt bearbeitet 03.11.2025 23:17:34
An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://devtools` origin. This could allow them to access cross-origin JSON content. This access is limited to "same site" documents by the Sit...
CVE-2024-9395
- EPSS 0.29%
- Veröffentlicht 01.10.2024 16:15:10
- Zuletzt bearbeitet 04.04.2025 14:39:09
A specially crafted filename containing a large number of spaces could obscure the file's extension when displayed in the download dialog. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affec...
CVE-2024-9396
- EPSS 0.15%
- Veröffentlicht 01.10.2024 16:15:10
- Zuletzt bearbeitet 04.04.2025 14:39:01
It is currently unknown if this issue is exploitable but a condition may arise where the structured clone of certain objects could lead to memory corruption. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thun...
CVE-2024-9397
- EPSS 0.19%
- Veröffentlicht 01.10.2024 16:15:10
- Zuletzt bearbeitet 18.03.2025 16:15:26
A missing delay in directory upload UI could have made it possible for an attacker to trick a user into granting permission via clickjacking. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.
CVE-2024-9398
- EPSS 0.6%
- Veröffentlicht 01.10.2024 16:15:10
- Zuletzt bearbeitet 18.03.2025 20:15:25
By checking the result of calls to `window.open` with specifically set protocol handlers, an attacker could determine if the application which implements that protocol handler is installed. This vulnerability affects Firefox < 131, Firefox ESR < 128....
CVE-2024-9399
- EPSS 0.26%
- Veröffentlicht 01.10.2024 16:15:10
- Zuletzt bearbeitet 14.03.2025 16:15:39
A website configured to initiate a specially crafted WebTransport session could crash the Firefox process leading to a denial of service condition. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < ...
CVE-2024-8900
- EPSS 0.22%
- Veröffentlicht 17.09.2024 19:15:29
- Zuletzt bearbeitet 18.03.2025 21:15:32
An attacker could write data to the user's clipboard, bypassing the user prompt, during a certain sequence of navigational events. This vulnerability affects Firefox < 129, Firefox ESR < 128.3, and Thunderbird < 128.3.
CVE-2024-8897
- EPSS 10.37%
- Veröffentlicht 17.09.2024 13:15:04
- Zuletzt bearbeitet 19.03.2025 16:15:30
Under certain conditions, an attacker with the ability to redirect users to a malicious site via an open redirect on a trusted site, may be able to spoof the address bar contents. This can lead to a malicious site to appear to have the same URL as th...
CVE-2024-7652
- EPSS 0.28%
- Veröffentlicht 06.09.2024 19:15:12
- Zuletzt bearbeitet 04.04.2025 14:38:20
An error in the ECMA-262 specification relating to Async Generators could have resulted in a type confusion, potentially leading to memory corruption and an exploitable crash. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbir...